The on-call page
RotaSul sends about 2,800 shipping emails an hour from its fulfillment queue. At 16:40, support started forwarding customer screenshots: the same shipment notice had arrived twice, with the same tracking number. The 18 tickets all followed a restart of the shipping-email worker during a routine host patch.
The provider dashboard showed 99.9% accepted requests and a p95 response time of 110ms. The publisher had accepted the events, the queue was reachable, and no other notification type was duplicated. The provider team says it does not retry a request after returning success.
You have 45 minutes to work the page. Do not delete the queue or change the provider. You may restart the worker, inspect its logs and the provider request log, and change the consumer.
Lab boundary
The publisher, RabbitMQ, worker, and email provider run locally. A controlled worker restart simulates the host patch; the provider is a deterministic local stand-in that records every accepted request. Production mail reputation, provider failover, and multi-region queue recovery are outside this incident.